CVE-2018-15635: XSS
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15635?
The severity of CVE-2018-15635 is medium with a severity value of 6.1.
How does CVE-2018-15635 affect Odoo Community and Odoo Enterprise?
CVE-2018-15635 affects Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier.
What can an attacker do with CVE-2018-15635?
An attacker can inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted payload.
How can I fix the cross-site scripting vulnerability in the Discuss App of Odoo?
To fix the vulnerability, update Odoo Community and Odoo Enterprise to versions 12.0 or later.
Is there any additional information available about CVE-2018-15635?
Yes, you can find more information about CVE-2018-15635 on the Odoo GitHub page: https://github.com/odoo/odoo/issues/32515